Showing posts with label Aditya K. Sood. Show all posts
Showing posts with label Aditya K. Sood. Show all posts

Thursday, August 9, 2018

ICS-CERT Publishes Two Advisories


Today the DHS ICS-CERT published two control system security advisories for products from NetComm and Crestron.

NetComm Advisory


This advisory describes four vulnerabilities in the NetComm 4G LTE Light Industrial M2M Router. The vulnerabilities were reported by Aditya K. Sood. NetComm has new firmware that mitigates the vulnerabilities. There is no indication that Sood has been provided an opportunity to verify the efficacy of the fix.

The four reported vulnerabilities are:

• Information exposure - CVE-2018-14782;
• Cross-site request forgery - CVE-2018-14783;
• Cross-site scripting - CVE-2018-14784; and
Information exposure through directory listing - CVE-2018-14785

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow for the exposure of sensitive information.

Crestron Advisory


This advisory describes four vulnerabilities in the Crestron TSW-X60 and MC3 products. The vulnerabilities were independently reported by Jackson Thuraisamy (via Security Compass) and Ricky “HeadlessZeke” Lawshae (via the Zero Day Initiative). Crestron has firmware versions available that mitigate the vulnerabilities. There is no indication that either researcher has been offered an opportunity to verify efficacy of the fix.

The four reported vulnerabilities are:

• OS command injection (2) - CVE-2018-11228 and CVE-2018-11229);
• Improper access control - CVE-2018-10630; and
• Insufficiently protected credentials - CVE-2018-13341

ICS-CERT reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow remote code execution with escalated system privileges.

NOTE: Is it just me or does it seem odd that the same vulnerabilities are found in a touch-screen device and a control system processor controller?

Thursday, December 17, 2015

ICS-CERT Publishes Three Advisories

This afternoon the DHS ICS-CERT published three advisories for control system vulnerabilities. The advisories affected products from eWON, Motorola, and Schneider.

eWON Advisory

This advisory describes multiple vulnerabilities in the eWON sa industrial router. The vulnerabilities were reported by Karn Ganeshen. eWON has developed a firmware update to mitigate the vulnerabilities, but there is no indication that Ganeshen has been provided the opportunity to verify the efficacy of the fix.

The vulnerabilities include:

• Weak session management - CVE-2015-7924;
• Cross-site request forgery - CVE-2015-7925;
• Weak RBAC controls - CVE-2015-7926;
• Stored cross-site scripting - CVE-2015-7927;
• Passwords not secured - CVE-2015-7928; and
• Post/get issues - CVE-2015-7929

ICS-CERT reports that a relatively low skilled attacker could remotely exploit the vulnerability.

A more detailed explanation of the individual vulnerabilities can be found on the eWON Security Enhancements page.

NOTE: This advisory has a much more detailed ‘Impact’ description than you find on most ICS-CERT advisories. Since these explanations would usually be the same for that given vulnerability across most platforms these explanations could be canned and served up with the appropriate vulnerability.

Motorola Advisory

This advisory describes twin vulnerabilities in the Motorola MOSCAD IP Gateway. The vulnerabilities were reported by Aditya K. Sood. Since support for this product was discontinued in 2012 there will be no patches or updates for this product.

The vulnerabilities are:

• Remote file inclusion - CVE-2015-7935; and
• Cross-site request forgery - CVE-2015-7936

ICS-CERT reports that a relatively unskilled attacker could remotely exploit these vulnerabilities to perform actions with the permissions of a valid user.

Schneider Advisory

This advisory describes a buffer overflow vulnerability in the Schneider Modicon M340 PLC. The vulnerability was discovered by Nir Giller. Schneider has produced a firmware pathe to mitigate the vulnerability but there is no report that Giller has been provided the opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively low skilled attacker could remotely exploit this vulnerability crash the device and perhaps run arbitrary code.


The Schneider Security Notification provides a very detailed explanation of how this vulnerability works.

Thursday, August 20, 2015

ICS-CERT Updates Two Rockwell Alerts

This afternoon the DHS ICS-CERT updated two alerts that it issued for Rockwell PLC’s last week. The updated alerts (here and here) have the same, single-sentence addition made:

“This vulnerability was discovered by Aditya K. Sood and presented by him at DefCon 2015 in Las Vegas, Nevada, on August 8, 2015.”


This means that all six of the DefCon related alerts that ICS-CERT published last week come from the same talk. Strange that none of the other talks about ICS security matters merited an alert, advisory or update of a previously issued advisory.

Wednesday, August 12, 2015

ICS-CERT Publishes Four DefCon 2015 Related Alerts

This afternoon the DHS ICS-CERT published alerts for four control system product vulnerabilities that were publicly disclosed during DefCon 2015 by Aditya K. Sood on August 8th. Proof-of-concept exploit code was presented at the conference.

Three of the four vulnerabilities were disclosed to ICS-CERT shortly before their release in Las Vegas, but they have not yet been able to complete the coordination/verification process with the vendors.

Moxa Alert

This alert describes three password related vulnerabilities in the Moxa ioLogik E2210 Ethernet Micro RTU controller. Two of these vulnerabilities are reportedly remotely exploitable.

Prisma Alert

This alert describes a cross-site request forgery vulnerability and an insufficiently protected password vulnerability in Prisma web products. Both of these vulnerabilities are reportedly remotely exploitable.

Schneider Alert

This alert describes three types of vulnerabilities in Schneider Electric’s Modicon M340 PLC Station P34 CPU modules. Those vulnerabilities include:

Hard-coded credentials (remotely exploitable);
Local file inclusion; and
Remote file inclusion (remotely exploitable).

Some of these vulnerabilities were already in the coordination/mitigation process while others had not been disclosed to either ICS-CERT or Schneider.

Kako Alert


This alert describes a hard-coded password vulnerability in KAKO HMI products. This vulnerability is remotely exploitable.
 
/* Use this with templates/template-twocol.html */